Ask an association executive which AI tools their organization uses and you will usually get a short, confident list. Ask which AI features are running inside the software they already pay for, and the answer changes shape.
That second category is almost always larger. Your AMS, your LMS, your certification platform, your email tool, your community software and your events system have all shipped AI capability over the past two years. Most of it arrived in a release note. Some of it arrived switched on.
None of that was a decision your organization made. It was a decision your vendors made, and then told you about — in a changelog, in a webinar you could not attend, in a footer of an email about something else.
It is worth being fair here, because the vendor-bashing version of this argument is both wrong and useless.
Your software vendors are not being careless. They are doing exactly what their incentives and their customers demand: shipping useful capability quickly, in a market where being six months behind on AI is an existential problem. Defaults are set to on because a feature nobody discovers is a feature that does not renew.
The asymmetry is not about competence or good faith. It is that your vendor's job is to ship value fast, and your job is to be able to answer for what runs on your members' data. Both are legitimate. They simply do not produce the same answer about what should be enabled, when, and with what disclosure.
Which means the gap is yours to close. Nobody else in that relationship is incentivised to close it for you.
The standard response to a governance question is a trust page: a security overview, a compliance badge, a paragraph about responsible AI. These are not worthless — a vendor that has thought about the question is better than one that has not.
But they are self-attestation. The vendor is describing its own practice, against criteria it selected, with no independent party checking and no consequence for overstating. That is a marketing artifact, not assurance.
A vendor cannot credibly certify itself. Not because vendors are dishonest, but because an assessment nobody can fail is not an assessment.
This matters more than usual right now because there is no established floor. In ISACA's 2026 poll of more than 3,400 professionals, only around 18% of organizations both require and enforce disclosure of AI use. When general practice is that thin, a confident trust page tells you very little about what is actually happening inside the product.
Not a procurement overhaul. Four questions, by email, to each vendor that touches member data. The written answer is the point — it creates a record, and it tends to produce more careful responses than a call.
1. Where does AI operate in the services you provide us? Ask for the specific features, not a philosophy. You are building an inventory, and this is the fastest way to fill in the part you cannot see from your own admin console.
2. Is any of our data used to train your models, or any third party's? Is that a contractual commitment or an account setting? This distinction is the one that catches people out. A great many vendors will tell you truthfully that your data is not used for training — because a toggle in your account is currently set that way. A setting can be changed by anyone with admin access, or reset in a migration. A contractual term cannot.
3. Which model providers and subprocessors are involved, and where does the data go? Your vendor is usually not the party running the model. The answer determines who actually holds your members' data, and under whose terms.
4. How will you notify us before enabling a new AI feature on our instance? The most useful question of the four, because it is forward-looking. If the answer is a release note, you now know that your governance depends on someone reading release notes.
Incident response is where vendor-run AI gets genuinely uncomfortable. If a tool starts producing wrong output at scale — an inaccurate answer repeated across thousands of member queries, a misfiring automated message — who can stop it, and how fast?
The ISACA poll found roughly 56% of professionals are unsure how long it would take to halt an AI system during a security incident, and around 39% do not know whether a documented shutdown or override process exists at all. Those are respondents whose profession is digital trust, reporting on systems their own organizations run.
When the system belongs to a vendor, the answer usually involves a support ticket. That is worth knowing before you need it, not after. It is a reasonable thing to ask, and a reasonable thing to have in writing.
If you are a trade association, one of these questions carries weight the others do not.
You hold pricing, volume, wage and market data submitted by companies that compete with each other, under antitrust discipline that predates all of this by decades. The controls around that data were designed for a world where the risk was a person seeing something they should not.
An AI feature that summarises, searches or surfaces patterns across your member data operates differently. Whether that data reaches a model, whether it is retained, and whether it could inform output shown to another member company are questions your existing information-sharing policies almost certainly do not address. This is a competition-law question as much as a privacy one, and it is worth raising with the counsel who advises you on information sharing rather than treating it as an IT matter.
We have no systematic data on how association software vendors actually handle AI defaults, training rights or notification — nobody has published it, ourselves included. The pattern described here comes from what organizations find when they look, not from a survey of vendors.
It is also entirely possible that your vendors answer all four questions well. Several will. The point is not that the answers will be bad; it is that you currently do not have them in writing, and the asking costs an afternoon.
We have written before about the gap between expecting disclosure and enforcing it, and about where AI has already entered certification programmes. This is the same problem approached from the supply side: you cannot disclose what you do not know, and you do not know what your vendors have not told you.
Two of the sixteen questions in our AI Trust Readiness Scorecard deal specifically with vendor-enabled features and model-training terms. It takes about five minutes, and there is no sign-up to see your result. If you would rather see how we assess this properly, the framework is published.